Who is responsible

Weekly is operated by Matías Monzalvo, an individual based in Buenos Aires, Argentina, who is the data controller for the information described here. For anything in this policy, write to support@weeklygrid.app.

What you give us

Creating an account

  • Email address. Used to sign you in, to send the six-digit verification code, and to reach you about your account.
  • Password, if you set one. It is stored hashed by our authentication provider. We never see it.
  • Date of birth. Used to confirm you meet the minimum age of 13. It is stored separately from your public profile, in a table only you and we can read. Other users never see it, and Weekly does not display your age or your birthday anywhere.
  • Display name and username. Both are public.
  • Sign in with Apple or Google. If you use one of these, the provider gives us your email address and, usually, your name. We do not receive your password or anything else from your account there. If you use Apple’s option to hide your email, we receive the relay address and that is what we use.

If you abandon sign-up part way through, the incomplete record is deleted automatically within two hours and the email address is free again.

Your profile

  • Profile photo, if you add one.
  • Bio, if you write one.
  • Instagram, Snapchat, TikTok and X usernames, if you add them. These are public by design — they exist to be shown on your profile.
  • Whether your account is private or public.

What you post

  • Photos. Each photo you add to a grid is stored in two sizes: the one shown in the grid and a smaller one used to load it quickly. Photos are cropped to the shape of the blocks you selected before upload.
  • Captions on your posts, comments you write, and likes you give.
  • The grids you create, including their titles, cover images and members.

Photos carry technical metadata — including, sometimes, the location where they were taken. Weekly does not read, use or display that metadata, and does not ask for location permission. If a photo’s embedded data matters to you, strip it before uploading.

When you report something

A report records who reported what, the reason you chose, and any detail you write. Reports are readable only by us — they are not visible to other users, including the person reported. We use them to review the content and act on it.

What using Weekly creates

  • Your social graph. Who you follow, who follows you, pending follow requests, and who you have blocked. Blocks are visible only to you.
  • Notifications. Records of likes, comments, follows, follow requests and grid invitations, and which of them you have read.
  • Which grids you have already seen. Weekly notes the grids that have passed through your feed so that it can put what you have not seen first. It is used for ordering your own feed and nothing else.
  • Push notification token, if you allow notifications, along with whether the device is iOS or Android, and which kinds of notification you have muted.
  • Grid invitation links you generate, and which of them have been used.
  • Technical logs. Our infrastructure provider records connection data, including IP address, timestamp and general request information, for security and debugging. These are retained for a limited period.

Permissions the app asks for

Each of these is optional, is requested only when the feature needs it, and can be changed in your device settings.

  • Photo library. To let you pick a photo for your grid. The app receives only the photos you select. It does not read or index your library.
  • Camera. To take a photo directly for a post. Weekly does not record audio or video — the microphone permission is explicitly disabled in the app.
  • Saving to your photo library. To save an image you chose to download.
  • Notifications. To send push notifications. Declining does not affect the in-app inbox.
  • Contacts. If you grant it, it is used on your device to help you find people to invite to a shared grid. Your address book is never uploaded to or stored on our servers.
  • Face ID. Used only to protect the stored session on your own device. Biometric data never leaves your device and we never receive it.

What we do not do

  • We do not sell or rent your personal information to anyone.
  • We do not include advertising SDKs, analytics SDKs or tracking pixels in the app, and we do not share data with data brokers or advertising networks.
  • We do not track you across other companies’ apps and websites, and Weekly does not request App Tracking Transparency permission because there is nothing to track.
  • We do not use your photos, captions or comments to train machine learning models.
  • We do not read your private messages, because Weekly does not have any.

Why we use your information

We use it to create and maintain your account, to show your grids to the people entitled to see them, to build your feed, to send notifications you have not muted, to review reports and enforce our Terms of Use, to keep the Service secure and working, and to comply with legal obligations.

If the GDPR applies to you, our legal bases are: performance of our contract with you, for everything needed to run your account and show your content; our legitimate interests, for security, abuse prevention, moderation and keeping the Service working; your consent, for device permissions and push notifications, which you can withdraw at any time in your device settings; and legal obligation, where the law requires us to retain or disclose something.

Who can see what

  • Your username, display name and profile photo are public. They appear in search, and they are used to build the link preview when someone shares a link to your profile — which means they can be read without an account.
  • If your account is public, your completed grids, your posts and your captions can be seen by anyone using Weekly, and may appear in Trending Grids and other discovery surfaces.
  • If your account is private, only followers you have approved can see your grids and posts.
  • In a shared grid, every member can see the grid and everything in it, regardless of anyone’s account privacy setting. Anyone with an invitation link can join.
  • Your photos are stored in private storage and are served through temporary links that expire after 24 hours. They are not sitting behind permanent public URLs.
  • Your email address and date of birth are never shown to other users.

One caveat that applies to every social app: a person who can see your content can screenshot it or save it. Setting an account to private limits who can see it; it cannot control what they do afterwards.

Who processes data for us

We use a small number of providers to run the Service. They act on our instructions and only for the purposes below.

  • Supabase — database, authentication, file storage and server functions. This is where your account and your photos live.
  • Expo — delivery of push notifications to your device, and over-the-air delivery of app updates.
  • Resend — sending us the email that notifies us of a moderation report.
  • Apple and Google — if you choose to sign in with them, and as the operators of the app stores through which Weekly is distributed.

We also disclose information where the law requires it, in response to a valid legal request, to protect someone’s safety, or to enforce our Terms. If the Service is ever transferred to someone else, the information would transfer with it, and we would tell you before that happened.

Where your information goes

Our providers operate internationally, so your information may be processed outside the country where you live, including in the United States and the European Union. Where the GDPR applies, transfers outside the European Economic Area rely on the European Commission’s Standard Contractual Clauses or on an adequacy decision.

How long we keep it

  • Your account information and content: for as long as your account exists.
  • Abandoned sign-ups: deleted automatically within two hours.
  • When you delete your account, your profile, your grids and your posts are deleted, including posts you contributed to a shared grid — those blocks become empty and the grid stays incomplete.
  • Backups: copies may persist in routine backups for a limited period after deletion, after which they are overwritten.
  • Reports and moderation records: retained after the account is gone, for as long as we need them to handle repeat abuse and to meet our legal obligations.
  • Technical logs: retained for a short period for security and debugging.

Your rights

Wherever you live, you can access and correct most of your information directly in the app — Settings lets you edit your profile, change your privacy setting, manage notifications, and delete your account.

If the GDPR or UK GDPR applies to you, you also have the right to request a copy of your data, to have it corrected or erased, to restrict or object to processing, to data portability, and to withdraw consent. You have the right to complain to your local data protection authority.

If you live in California, you have the right to know what personal information we collect and how we use it, to request deletion or correction, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA.

If you live in Argentina, you have the rights of access, rectification, update and suppression under Law 25.326, and you may address the Agencia de Acceso a la Información Pública.

To exercise any of these, write to support@weeklygrid.app from the email address on your account. We respond within 30 days.

Children

Weekly is not for children under 13. We ask for your date of birth during sign-up and an account cannot be created if it does not meet the minimum age. We do not knowingly collect personal information from anyone under 13.

If you are a parent or guardian and you believe your child under 13 has created an account, write to support@weeklygrid.app. We will delete the account and its content.

How we protect it

Access to every row of data is enforced by the database itself rather than by the app, so a modified client cannot read what it should not. Photos live in private storage and are served through links that expire. Your session is stored in your device’s secure storage. Connections use TLS.

No service can promise perfect security. If a breach ever affects your personal information, we will notify you and the relevant authorities as the law requires.

Changes to this policy

We will update this policy as Weekly changes. When a change is material, we will update the date at the top and notify you in the app or by email before it takes effect.

Contact

Questions, requests about your data, or anything else: support@weeklygrid.app.